Export limit exceeded: 398909 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16542 1 Wordpress-extensions 1 Import And Export Users And Customers 2026-09-28 4.1 Medium
The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks.
CVE-2026-92540 1 Wordpress-extensions 1 Import And Export Users And Customers 2026-09-28 7.2 High
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
CVE-2026-92541 1 Wordpress-extensions 1 Import And Export Users And Customers 2026-09-28 7.2 High
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.